Skip to content
Calcrivo

Exception Risk Calculator

Score a policy exception or risk acceptance: control bypassed, exposure window, blast radius and compensating controls, with an approval level.

Inputs

days
%
systems
renewals

Exception Risk Level

Medium

Exception Risk Score

3.00of 5

Share of the Maximum Score

59.9%

Maximum Defensible Window

180days

Required Approval Level

Head of security

Window Verdict

Requested window is proportionate to the risk, and should expire automatically rather than on request

Justification Verdict

Business value is weak relative to the risk: push back and fund the fix rather than renewing the exception again

Step by step

  1. Values used

    Criticality of the control being bypassed = 4 — Key control, no alternative; Requested exception window = 90 days; Sensitivity of the data or system in scope = 4 — Personal data; Compensating control strength = 40 %; Systems or endpoints covered by the exception = 12 systems; Any affected system is internet-facing = Yes; Times this exception has already been renewed = 2 renewals; Strength of the business justification = 3 — Delivery deadline

  2. Exception Risk

    Exception risk = (0.30 × control criticality + 0.25 × data sensitivity + 0.20 × window band + 0.15 × blast-radius band + 0.10 × internet exposure) × compensating factor × renewal uplift.

  3. Exception Risk Level

    = Medium

  4. Exception Risk Score

    = 3.00 of 5

  5. Share of the Maximum Score

    = 59.9

  6. Maximum Defensible Window

    = 180 days

  7. Required Approval Level

    = Head of security

  8. Window Verdict

    = Requested window is proportionate to the risk, and should expire automatically rather than on request

How it works

Time is treated as a risk factor in its own right, because the same technical gap is a different exposure for thirty days than for three years. Compensating controls reduce the score by at most 60%, and each previous renewal adds an uplift — a permanent exception is not an exception, it is an undocumented change to the policy, and the arithmetic should make that visible. Exception registers are where security debt accumulates quietly, and mapping a score to a named approver and a maximum window is what stops a temporary bypass becoming the architecture. These are management estimates to support consistent decisions, not a compliance determination.

Formula

Exception Risk

Exception risk = (0.30 × control criticality + 0.25 × data sensitivity + 0.20 × window band + 0.15 × blast-radius band + 0.10 × internet exposure) × compensating factor × renewal uplift.

window band
1 for 30 days or less, rising to 5 beyond a year
blast-radius band
Systems affected, banded 1–5
renewal uplift
+8% per previous renewal, capped at five

Frequently Asked Questions

How is Exception Risk calculated?

Exception risk = (0.30 × control criticality + 0.25 × data sensitivity + 0.20 × window band + 0.15 × blast-radius band + 0.10 × internet exposure) × compensating factor × renewal uplift. Time is treated as a risk factor in its own right, because the same technical gap is a different exposure for thirty days than for three years. Compensating controls reduce the score by at most 60%, and each previous renewal adds an uplift — a permanent exception is not an exception, it is an undocumented change to the policy, and the arithmetic should make that visible.

Why does Exception Risk matter?

Exception registers are where security debt accumulates quietly, and mapping a score to a named approver and a maximum window is what stops a temporary bypass becoming the architecture. These are management estimates to support consistent decisions, not a compliance determination.

What values do I need to enter?

This calculator takes 8 inputs: Criticality of the control being bypassed, Requested exception window, Sensitivity of the data or system in scope, Compensating control strength, Systems or endpoints covered by the exception, Any affected system is internet-facing, Times this exception has already been renewed, Strength of the business justification. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

What should happen when an exception expires?

The control comes back on by default and the exception has to be re-argued with fresh evidence. Exceptions that lapse into silent permanence are the ones that appear in incident reports, and automatic expiry is the only mechanism that reliably prevents it.

Can a compensating control make an exception risk-free?

No, and capping its benefit at 60% is deliberate. A compensating control was designed for a different purpose, is rarely tested against this specific risk, and often shares a dependency with the control being bypassed.

You might also need